Red Team Security
Detection and Hunting of Golden SAML Attack
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Detection and Hunting of Golden SAML Attack
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
How to export LAPS password with Powershell
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
How to export LAPS password with Powershell
submitted by /u/ahmedm0hamed007
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Powershell+VBScript Post-Exploitation Tool w/ Persistence
https://github.com/jeffjbowie/Weaponry/blob/master/SlimLOLC2.ps1
After learning about concepts of "living off the land" as well as researching various threat feeds, I wanted to make a minimal tool for running commands from a URL, with added persistence.
* Check for "mutex" file in
* If mutex doesn't exist, drops VBScript payload to
* Clones an existing scheduled task label, appending random characters to end , being mindful of 255 character limitation.
* Upon execution of scheduled task , connects to C2 URL, running desired command in either Powershell or Windows Command Processor.
submitted by /u/jeff-j-bowie
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Powershell+VBScript Post-Exploitation Tool w/ Persistence
https://github.com/jeffjbowie/Weaponry/blob/master/SlimLOLC2.ps1
After learning about concepts of "living off the land" as well as researching various threat feeds, I wanted to make a minimal tool for running commands from a URL, with added persistence.
* Check for "mutex" file in
$env:temp* If mutex doesn't exist, drops VBScript payload to
$env:temp* Clones an existing scheduled task label, appending random characters to end , being mindful of 255 character limitation.
* Upon execution of scheduled task , connects to C2 URL, running desired command in either Powershell or Windows Command Processor.
submitted by /u/jeff-j-bowie
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Dump lsass with Windows OS native tools
submitted by /u/cx-4
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Dump lsass with Windows OS native tools
submitted by /u/cx-4
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
One thousand and one ways to copy your shellcode to memory (VBA Macros)
submitted by /u/NoUseForANick
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
One thousand and one ways to copy your shellcode to memory (VBA Macros)
submitted by /u/NoUseForANick
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
IronNetInjector: Turlaβs New Malware Loading Tool
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
IronNetInjector: Turlaβs New Malware Loading Tool
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
First example of malicious code that natively targets Apple Silicon (M1)
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
First example of malicious code that natively targets Apple Silicon (M1)
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Red Team Security
Masslogger campaigns exfiltrates user credentials
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Masslogger campaigns exfiltrates user credentials
submitted by /u/malware_bender
[link] [comments]
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Bug Bounty on Medium
Exposed Unsafe ActiveX Method [CWE-618]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*4ZaQXs_vH6lIlM6jvuFR9Q.jpeg
Exposed Unsafe ActiveX Method weakness describes exposure of dangerous ActiveX methods that perform actions outside the browserβs securityβ¦
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Exposed Unsafe ActiveX Method [CWE-618]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*4ZaQXs_vH6lIlM6jvuFR9Q.jpeg
Exposed Unsafe ActiveX Method weakness describes exposure of dangerous ActiveX methods that perform actions outside the browserβs securityβ¦
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Bug Bounty on Medium
IDOR Vulenebility with empty response still exposing sensitive details of customers!
Hello thereπ!
For many days I was thinking of sharing my bug bounty experience with the community and finally writing my first write-up.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
IDOR Vulenebility with empty response still exposing sensitive details of customers!
Hello thereπ!
For many days I was thinking of sharing my bug bounty experience with the community and finally writing my first write-up.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Bug Bounty on Medium
NULL Pointer Dereference [CWE-476]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*QC2szUXNDa3JsW7LEeQ0YA.jpeg
NULL Pointer Dereference weakness occurs where software dereferences a pointer with a value of NULL instead of a valid address.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
NULL Pointer Dereference [CWE-476]βββThe Hacktivists
https://cdn-images-1.medium.com/max/2600/1*QC2szUXNDa3JsW7LEeQ0YA.jpeg
NULL Pointer Dereference weakness occurs where software dereferences a pointer with a value of NULL instead of a valid address.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Exploiting XML External Entity (XXE) via image file upload
This lab lets users attach avatars to comments and uses the Apache Batik library to process avatar image files.Continue reading on The Startup Β»
Read more...
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
This lab lets users attach avatars to comments and uses the Apache Batik library to process avatar image files.Continue reading on The Startup Β»
Read more...
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hacking Articles Tips Tricks Videos Tutorials
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Kali Linux Tutorials
SSRFuzz : A Tool To Find Server Side Request Forgery Vulnerabilities, With CRLF Chaining Capabilities
SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities. Why? I wanted to write a tool in Golang for concurrency I wanted to fuzz parameters for SSRF vulnerablities, as well as fuzz both paths and parameters for CRLF injections I was inspired by Orangeβs work for chaining these types [β¦]
The post SSRFuzz : A Tool To Find Server Side Request Forgery Vulnerabilities, With CRLF Chaining Capabilities appeared first on Kali Linux Tutorials.
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
SSRFuzz : A Tool To Find Server Side Request Forgery Vulnerabilities, With CRLF Chaining Capabilities
SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities. Why? I wanted to write a tool in Golang for concurrency I wanted to fuzz parameters for SSRF vulnerablities, as well as fuzz both paths and parameters for CRLF injections I was inspired by Orangeβs work for chaining these types [β¦]
The post SSRFuzz : A Tool To Find Server Side Request Forgery Vulnerabilities, With CRLF Chaining Capabilities appeared first on Kali Linux Tutorials.
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hacking Articles Tips Tricks Videos Tutorials
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hacking on Medium
Hack The BoxβββReel2 10.10.10.210 Writeup
https://cdn-images-1.medium.com/max/743/0*r01nfdAwIf9_mlyM.png
Reel2 starts by gathering names from users in a Social Networking Service and create a new form of usernames then spray a seasonalβ¦
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hack The BoxβββReel2 10.10.10.210 Writeup
https://cdn-images-1.medium.com/max/743/0*r01nfdAwIf9_mlyM.png
Reel2 starts by gathering names from users in a Social Networking Service and create a new form of usernames then spray a seasonalβ¦
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hacking Articles Tips Tricks Videos Tutorials
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hacking on Medium
Akun Whatsapp Terkena Hack
https://cdn-images-1.medium.com/max/720/1*ecHcbXgg0bc6mUUnuztFLw.jpeg
Sebelum membahas lebih jauh membahas tentang kena Hack Whatsapp kita kenali dulu awal mula terkena hacknya.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Akun Whatsapp Terkena Hack
https://cdn-images-1.medium.com/max/720/1*ecHcbXgg0bc6mUUnuztFLw.jpeg
Sebelum membahas lebih jauh membahas tentang kena Hack Whatsapp kita kenali dulu awal mula terkena hacknya.
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hacking Articles Tips Tricks Videos Tutorials
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hacking on Medium
Hack The BoxβββForest: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*DIgXhb4uBvyhN2JDXX3EWw.png
Hack The BoxβββForest: Walkthrough (without Metasploit)
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π
Hack The BoxβββForest: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*DIgXhb4uBvyhN2JDXX3EWw.png
Hack The BoxβββForest: Walkthrough (without Metasploit)
Continue reading on Medium Β»
ππ§π»βπ»@hacking_Attackπ§π»βπ»π